Didsbury Runners will directly store your personal data in the form of your name, gender, and email address, age, contact details, and medical information. We use this data to provide medical assistance in an emergency, monitor attendance, provide you with statistics, and contact you with important information in the form of direct emails and a newsletter. Didsbury Runners will never pass your personal information on to a third party except where explicitly required and communicated - as per the England Athletics subscription for example. To use this information we require your explicit consent. To view the full Didsbury Runners GDPR policy please read below:
Didsbury Runners GDPR Policy
The implementation of this policy is the responsibility of the Chair of Didsbury Runners, acting through delegation to the committee members.
Adherence to the policy is part of the duties of the committee members, and any member of the club who is acting in an executive capacity for the club.
Didsbury Runners will collect, hold and process personal data from our members only for the purpose of providing the service of operating a running club. We will always gain explicit consent from members either on joining or membership renewal, to hold and process this data.
We will store and process data securely, using systems we know to be GDPR compliant.
We will retain data only for the purposes for which consent has been given, and will delete data in a timely fashion.
We will allow members to request deletion of data, to see the data we hold on their behalf, to request rectification of data, and to cease from processing of data.
We will handle data in accordance with our stated privacy policy, and according to our information security GDPR Statement
We have carried out an information audit and have identified our data flows. These are, and will remain, very limited. We hold personal contact information for our members to allow us to contact them, and for them to to be known to us, when they contact us.
The lawful basis for our holding this data is through their explicit consent. We obtain explicit consent when members sign up as members, and when they renew their membership which is done annually. We inform members through access to this statement, and through access to our constitution, about their privacy rights. They have a right to access their data that we hold, a right to erasure and disposal of that data, and a right to restrict processing. However, since we only hold data for the purpose of being able to communicate with them, restriction on processing and holding is incompatible with membership.
Our data protection policy and our information policy is minuted and managed at and through committee meetings. Information security breaches will be communicated to committee members and then to club members. The committee is responsible for information security and for GDPR compliance, and the Chair of the committee is the individual with executive authority for these matters.
We will have a written contract with any data processor that we use.